Skip to content
AsliPDF
हि

Security

Check for yourself that your files never leave your device

Anyone can write “your files are private”. Here is how to see it for yourself in a minute, what your browser enforces on the site's behalf, and what the 79 tools do and don't send.

What kind of site this is

AsliPDF is a static website: its pages, scripts and engines are files served exactly as they are. There is no application server behind it, no database and no upload endpoint. The tools are programs that run inside your browser tab, on your own device, using WebAssembly and JavaScript.

So the privacy isn't a policy that someone has to keep following. It is what the site is made of: there is nowhere for a file to be sent. The sections below let you confirm that instead of believing it.

Check it in a minute: watch the network

Every request a web page makes is listed in your browser's developer tools. Using any AsliPDF tool while you watch shows what leaves your device.

  1. 01

    Open the tools

    Press F12 (or Ctrl+Shift+I; on a Mac, Cmd+Option+I). In Safari, turn on the Develop menu first. Click the Network tab.

  2. 02

    Start from a clean list

    Open any tool, say Merge PDF, then click the clear button (the circle with a line through it) so the list is empty.

  3. 03

    Use the tool

    Add two PDFs and click Merge. Watch the list while you do it.

  4. 04

    Read what appeared

    You will see the page's own scripts and perhaps an engine file loading from aslipdf.com. Type method:POST in the filter box: nothing is listed. No request carries your file, because none is made.

Two more tests take seconds. Try to find an upload endpoint: open https://www.aslipdf.com/api/upload in a new tab. The page doesn't exist, because the site has no API at all. Turn the network off: add your files to a tool, wait for its options to appear, then switch your device to airplane mode and run it. Most tools carry on working, because they never needed the network. (A few fetch an engine or fonts the first time you use them, OCR and PDF to PDF/A for instance; use those once with the network on before you test.)

What your browser enforces

Every page of the site arrives with a Content-Security-Policy, a rule the browser itself applies to the page. The lines that matter here say where the page may connect, and that nothing may be posted elsewhere:

default-src 'self';
connect-src 'self' blob: data: https://cdn.jsdelivr.net;
form-action 'self';
frame-ancestors 'none';
object-src 'none'

connect-src lists where scripts on the page may open a connection: this site, and the one CDN that serves OCR language models. A script trying to send your file to any other address is blocked by the browser, not by our good behaviour. You can read the full header in the Network tab: click the first request, then Headers.

Everything that is sent, and what it carries

Nothing is left out of this list.

WhatDetailsWhat it carries
The page and its codeHTML, scripts and styles, from aslipdf.com. Cached after the first visit.Nothing about you or your files.
Processing enginesWebAssembly engines for OCR, HEIC photos, PDF decryption, JPEG compression, and fonts for PDF/A. Fetched from aslipdf.com the first time a tool needs one.Nothing: they are downloads to you.
OCR language modelsWhen you run OCR in a language, its model (a few MB) comes from the jsDelivr CDN. This is the only request the page may make to another site.Nothing about your document. It is a download, and it is cached afterwards.
Usage countsVercel Web Analytics, without cookies, counts page views and four tool events: a file was added, a result was made, it was downloaded, an error was shown.The tool's name (and how many files were added). Never file names, contents, sizes or error text.
Hosting logsThe host that serves the site sees the ordinary details of any web request: IP address, browser, time.No file data: no file is ever in a request.

What stays on your device

  • Your file is read into your browser tab's memory, worked on there, and the result is saved to your Downloads folder. Closing the tab clears the memory.
  • Your theme (light or dark) and the tools you opened recently, so search can suggest them, are kept in the browser's localStorage.
  • A workflow you save in Batch PDF is kept there too: its steps and settings only. A password you typed for a Protect step is never saved.

What this can't protect

Processing on your device is only as private as the device. A browser extension you've allowed to read pages can read a document being worked on. A shared or public computer can keep the downloaded result in its Downloads folder. And where you send the result is up to you. For something sensitive, use a private window without extensions, and delete the download when you're done.

Built on open-source engines

The code that reads and writes your documents comes from well-known open-source projects, bundled into this site rather than fetched from anywhere else: pdf-lib and PDF.js for PDFs, qpdf for encryption, Tesseract for OCR, MozJPEG for image compression, and the Noto, Liberation and Foxit fonts. Their licences are permissive, and nothing in this list talks to a server.

More: the privacy policy, how the site is built, and sharing ID documents safely.

Questions people ask

Something not covered? Ask us.

Can AsliPDF see my files?

No. There is no server that receives them: the site has no application backend, database or upload endpoint, only pages, scripts and engines that run in your browser. A file never leaves your device, so there is nothing for us to see, keep, lose or be asked to hand over.

Services that upload files promise to delete them after a while. Why isn't that promise needed here?

A promise is needed when your file is sent to a computer you don't control: you rely on what its owner does with it. Here the file is never sent, so there is nothing to delete and nothing to rely on. You can check that the file isn't sent; you can't check a deletion.

Is it safe for an Aadhaar card, a PAN card or a bank statement?

The processing is as private as it can be: it happens on your device. What matters next is where the result goes. The file you download is an ordinary file on your device, and anything you then upload or send is outside AsliPDF. For ID documents, see the guide on sharing them safely.

Could the site change tomorrow and start uploading?

Any website can change its code, and you shouldn't take anyone's word for what it does today. That's why this page shows how to check: the browser's Network tab shows every request the page makes, and the Content-Security-Policy tells the browser to refuse connections to anywhere else. Both are checks you can repeat on any visit.

Do browser extensions matter?

Yes. An extension you've allowed to read pages can read what is on a page, including a document being worked on, whatever site it is. If you are handling something sensitive, use a private window with extensions off, or a browser profile without them.

What if I find a security problem?

Please email contact@aslipdf.com with the subject "Security". Say what you found and how to reproduce it. We read every report.